2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-34141 | HIGH | 8 | 0.6% | Jul 17, 2023 | A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions ... |
| CVE-2023-34140 | MEDIUM | 6.5 | 0.3% | Jul 17, 2023 | A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series fir... |
| CVE-2023-34139 | HIGH | 8.8 | 0.7% | Jul 17, 2023 | A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4... |
| CVE-2023-34138 | HIGH | 8 | 0.6% | Jul 17, 2023 | A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 throu... |
| CVE-2023-33012 | HIGH | 8.8 | 10.1% | Jul 17, 2023 | A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.3... |
| CVE-2023-33011 | HIGH | 8.8 | 0.3% | Jul 17, 2023 | A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmw... |
| CVE-2023-37475 | HIGH | 7.5 | 0.8% | Jul 17, 2023 | Hamba avro is a go lang encoder/decoder implementation of the avro codec specification. In affected versions a well-craf... |
| CVE-2023-34669 | HIGH | 7.5 | 0.7% | Jul 17, 2023 | TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_mod... |
| CVE-2023-28767 | HIGH | 8.8 | 0.4% | Jul 17, 2023 | The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through ... |
| CVE-2023-3615 | HIGH | 8.1 | 0.3% | Jul 17, 2023 | Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a ne... |
| CVE-2023-3614 | LOW | 3.3 | 0.3% | Jul 17, 2023 | Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server r... |
| CVE-2023-3613 | LOW | 3.5 | 0.3% | Jul 17, 2023 | Mattermost WelcomeBot plugin fails to to validate the membership status when inviting or adding users to channels allowi... |
| CVE-2023-3593 | MEDIUM | 6.5 | 0.5% | Jul 17, 2023 | Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdow... |
| CVE-2023-3591 | HIGH | 8.2 | 0.3% | Jul 17, 2023 | Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created. |
| CVE-2023-3590 | HIGH | 7.5 | 0.4% | Jul 17, 2023 | Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments. |
| CVE-2023-3587 | LOW | 2.7 | 0.4% | Jul 17, 2023 | Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any us... |
| CVE-2023-3586 | MEDIUM | 5.4 | 0.2% | Jul 17, 2023 | Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, re... |
| CVE-2023-3585 | MEDIUM | 4.3 | 0.4% | Jul 17, 2023 | Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially... |
| CVE-2023-3584 | LOW | 3.1 | 0.3% | Jul 17, 2023 | Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the... |
| CVE-2023-3582 | MEDIUM | 4.3 | 0.3% | Jul 17, 2023 | Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated ... |
| CVE-2023-3581 | HIGH | 8.1 | 0.2% | Jul 17, 2023 | Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to acc... |
| CVE-2023-3577 | MEDIUM | 4.3 | 0.3% | Jul 17, 2023 | Mattermost fails to properly restrict requests to localhost/intranet during the interactive dialog, which could allow an... |
| CVE-2023-37985 | HIGH | 8.8 | 0.2% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 ver... |
| CVE-2023-37974 | HIGH | 8.8 | 0.2% | Jul 17, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Justin Klein WP Social AutoConnect plugin <= 4.6.1 versions. |
| CVE-2023-36656 | MEDIUM | 5.4 | 1.0% | Jul 17, 2023 | Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now